Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 17th, 2008, 11:58 AM
Warhammer Warhammer is offline
Infrequent Poster
 
Join Date: Aug 2008
Location: North Carolina
Posts: 1
Default Virtumonde Adware

I just spent the last two days trying to eliminate Virtumonde on my PC. It was a very amazing little bastard. It effectively took out my ability to do any kind of search using google or yahoo or anything related to searches on the Internet.

I use Comodo Firewall with Comodo Defender AND ESET NOD 32. The file I got it from was scanned (I have the latest updates) and no warning came from the scan. And I have the scan setting on the highest paranoid level you can get. When the PC got infected, the ESET detected the threat and prevented it from opening up the webpage.

After many using many different attempts with programs to eliminate it, I used Combofix to finally cure the virus.

The problem(s) I have with this is:

1. Why wasn't the virus detected during the scan?
2. Why couldn't the program get rid of the virus once it was detected?
3. Why doesn't the ESET knowledge base come up with any hits when I type in Virtumonde?

From what I can gather from google searches, this is a pretty well-known virus. I know no virus scanner is 100%, but this is the first time in 13 years that I have gotten hit with a virus after scanning the downloaded program.
  #2  
Old August 17th, 2008, 12:02 PM
Lusitano Lusitano is offline
Infrequent Poster
 
Join Date: Jun 2008
Posts: 20
Default Re: Virtumonde Adware

The problem is that there are so many Virtumonde's variants, no AV can detect them all as new ones appear at every minute.
  #3  
Old August 17th, 2008, 12:49 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Virtumonde Adware

Virtumonde is quite resistant to remove. You can use Undll to remove an already injected Virtumonde dll.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums